Who we serve

Sectors where the evidence has to hold

The work changes shape with the sector, because the standard being applied and the party asking for proof both change with it. Six groups account for most of it.

01

Financial services and payments

Banks, insurers, payment institutions, e-money firms and market infrastructure operating under supervisory scrutiny. Typical work is DORA operational resilience assessment, ICT third-party risk review, threat-led penetration testing, PCI DSS scope and readiness assessment, and the evidence packages a supervisor asks to see.

02

Manufacturing, energy and critical infrastructure

Industrial operators, utilities, transport and logistics organisations where operational technology and safety sit alongside information systems. Typical work is NIS2 applicability and gap assessment, OT and industrial control system architecture vetting, supplier vetting across engineering supply chains, and incident response planning that accounts for physical process.

03

Technology and product companies

Software, hardware and connected-product organisations that ship to European markets. Typical work is Cyber Resilience Act readiness for products with digital elements, secure development and DevSecOps assessment, cloud and identity architecture vetting, penetration testing across product and platform, and AI system vetting where models form part of the product.

05

Public sector and European institutions

National authorities, agencies, and European institutions and bodies, together with the programmes they fund. Typical work is audit of EU-funded projects, assessment against ENISA and European Commission frameworks, security governance and risk methodology, and independent assurance over programmes delivered by third parties.

06

Consultancies and systems integrators

Organisations that bring in certified specialists for client programmes and bids. Typical work is named specialist input to client-facing assessments, independent technical review inside a wider delivery programme, and certification-holder participation in tender and framework submissions.

Tell us what has to be proved

Describe the system, the standard and the party asking for evidence. We will tell you what an assessment would cover.

Contact